Small refactor of Authz

This commit is contained in:
Theodor S. Midtlien
2026-09-18 11:28:16 +02:00
parent 6dcb1374e9
commit cb9d2ee3bb
3 changed files with 109 additions and 105 deletions
+23
View File
@@ -1,5 +1,9 @@
package ipcauth
import (
"github.com/netbirdio/netbird/client/proto"
)
const servicePath = "/daemon.DaemonService/"
// Request is what a rule decides on: the authorization plus the state and the
@@ -50,6 +54,25 @@ type MethodPolicy struct {
Command string
}
// RequireHolderForFullStatus escalates a StatusRequest that asks for peer detail
// or for probes to be run.
func RequireHolderForFullStatus(r Request) error {
statusReq, ok := r.Msg.(*proto.StatusRequest)
if !ok {
return nil
}
if r.Level < AuthzLevelSessionHolder {
if statusReq.GetFullPeerStatus {
statusReq.GetFullPeerStatus = false
}
if statusReq.ShouldRunProbes {
statusReq.ShouldRunProbes = false
}
return nil
}
return RequireLevel(AuthzLevelSessionHolder)(r)
}
// methodPolicies is the complete authorization surface. Every RPC on
// DaemonService appears here exactly once.
var methodPolicies = map[string]MethodPolicy{